Skip to content

Configure Restricted Access Control in SharePoint for Copilot

Billy Peralta

Microsoft documentation checked 10 min read

Smartphone on wooden table displaying colorful code or terminal text

Topics: SharePoint Governance, External Sharing, Microsoft 365 Copilot

To configure restricted access control SharePoint settings so Copilot and external sharing cannot reach high‑risk sites, you enable site‑level access restriction in the SharePoint admin center, scope it to specific sites using control groups, and optionally block sharing outside those groups. This guide gives you the exact steps and a repeatable test to confirm it works.

The focus is one control: restricted access control in SharePoint Advanced Management. You can apply it quickly to a handful of risky sites while you work on broader permissions and sharing cleanup.

What restricted access control does for Copilot and sharing

Restricted site access control in SharePoint Online (also called restricted access control or site access restriction) is a policy that limits access to a site and its content to users in specific Microsoft 365 or Microsoft Entra security groups.Restricted site access control

Users who are not in a control group cannot open the site or its files, even if they had prior permissions or shared links. The policy applies when a user attempts to open a site or file, and users blocked by it see an access denial page.

You can apply the policy to Microsoft 365 group‑connected sites, Teams‑connected sites, nongroup sites, and OneDrive, and configure up to 10 Microsoft 365 or Microsoft Entra security groups per site, including dynamic security groups, so membership can follow HR attributes.

Restricted access control is honored in organization‑wide search results and Microsoft Copilot experiences, so content from protected sites no longer appears for users who are blocked by the policy. Microsoft Copilot only surfaces organizational data to which each user has at least view permissions through Microsoft Graph.Data, privacy, and security for Microsoft Copilot Together, these behaviors make restricted access control a practical way to ring‑fence messy or sensitive sites during a Copilot rollout.

For broader context on SharePoint Advanced Management controls before Copilot expands access, see SharePoint Advanced Management: What to Review Before Copilot Expands Access.

Before you start: licensing, roles, and prerequisites

Restricted access control is part of SharePoint Advanced Management (SAM).SharePoint Advanced Management overview Review the SAM prerequisites article for licenses, admin roles, and the SharePoint Online Management Shell module before you plan a rollout. You turn the feature on and manage its tenant‑level options in the SharePoint admin center or SharePoint Online Management Shell. As a SharePoint administrator, you can also delegate management of restricted access control to site administrators, who then provide a justification whenever they change their site’s setting.

For an initial test, pick one or two high‑risk sites, select a user who currently has access but should lose it when the site is ring‑fenced, and make sure that user has a Copilot experience that uses organizational data, such as a Microsoft 365 Copilot (Premium) user.Microsoft Copilot overview

If you need help designing a broader governance model beyond this specific control, see SharePoint Governance Consulting.

Enable restricted access control at the tenant level

You must turn on site‑level access restriction for your organization before you can configure restricted access control on individual sites.Restricted site access control

Turn on site‑level access restriction in the SharePoint admin center

  1. In the SharePoint admin center, go to Policies > Access control.
  2. Select Site-level access restriction.
  3. Choose Allow access restriction, then select Save.

Once this setting is enabled, restricted access control options are available for sites.

Enable restricted access control with PowerShell (optional)

You can also enable site‑level access restriction by using PowerShell.

Set-SPOTenant -EnableRestrictedAccessControl $true

Microsoft notes that it can take up to one hour for this command to take effect in the service.

Delegate management to site admins (optional)

By default, site admins cannot change restricted access control settings. As a SharePoint administrator, you can delegate this control so site admins can manage their own site’s access restriction, with justification logged for each change.

Set-SPOTenant -DelegateRestrictedAccessControlManagement $true

Get-SPOTenant | Select-Object DelegateRestrictedAccessControlManagement

For Microsoft 365 Multi‑Geo tenants, run these commands separately for each geo where you want delegation.

Restrict access on specific SharePoint sites

After tenant‑level access restriction is enabled, you can configure restricted access control on selected SharePoint sites so that only users in specified Microsoft 365 or Microsoft Entra security groups can reach them.Restricted site access control

Configure restricted access control in the SharePoint admin center

  1. In the SharePoint admin center, go to Sites > Active sites.
  2. Select the high‑risk site you want to protect (for example, Finance). The site details panel opens.
  3. On the Settings tab, find Restricted site access, then select Edit.
  4. Check Restrict SharePoint site access to only users in specified groups.
  5. Add one or more Microsoft 365 groups or Microsoft Entra security groups that should be allowed to access this site.
  6. Select Save.

For group‑connected sites, the Microsoft 365 group linked to the site is added as the Default group in the control group list. You can keep it and add up to nine more Microsoft 365 or Microsoft Entra security groups, for a maximum of 10 per site.

Adding a group to the restricted access control list does not grant permissions by itself. Users must have site or content permissions and be members of at least one control group, otherwise access is denied.

Configure restricted access control with PowerShell

You can also manage site‑level restricted access control by using PowerShell.

Set-SPOSite -Identity https://contoso.sharepoint.com/sites/Finance -RestrictedAccessControl $true

# Add control groups by GUID
Set-SPOSite -Identity https://contoso.sharepoint.com/sites/Finance \
  -AddRestrictedAccessControlGroups 11111111-1111-1111-1111-111111111111,22222222-2222-2222-2222-222222222222

# View current settings
Get-SPOSite -Identity https://contoso.sharepoint.com/sites/Finance | \
  Select RestrictedAccessControl, RestrictedAccessControlGroups

Use -RestrictedAccessControlGroups to replace the full list, -RemoveRestrictedAccessControlGroups to remove specific groups, and -ClearRestrictedAccessControl to reset site access restriction entirely.

Configure Teams shared and private channel sites

Shared and private channel sites in Microsoft Teams are separate site collections and are not connected to the parent team’s Microsoft 365 group.Restricted site access control Restricted access control configured on the team‑connected site does not automatically apply to these channel sites, so configure it separately for each shared or private channel site as a nongroup‑connected site.

For shared channel sites, restricted access control applies only to internal users in the resource tenant, and external participants from another tenant continue to be governed by the shared channel permissions. Adding people to the security group or Microsoft 365 group does not give them access to the Teams channel, so align membership in the Teams channel and the restricted access control groups.

Align external sharing with restricted access control

Restricted access control governs who can open a site or file, but by default SharePoint sharing actions do not follow this policy.Restricted site access control Users can share sites and content with people outside the control groups, and those recipients are then blocked by restricted access control when they try to open the content.

SharePoint has external sharing settings at both the organization and site levels; to allow external sharing on any site, it must be allowed at the organization level, and site‑level settings can be the same or more restrictive. If the two differ, the most restrictive value applies.Overview of external sharing

Block sharing outside restricted access control groups

To prevent confusing invitations and align sharing behavior with restricted access control, you can restrict sharing of sites and content to only users in the restricted access control groups.

Set-SPOTenant -AllowSharingOutsideRestrictedAccessControlGroups $false

With this setting, sharing with users who are not in any restricted access control group is blocked. Sharing with groups is allowed only for Microsoft Entra security groups or Microsoft 365 groups that are in the site’s restricted access control list, and sharing is not allowed to other groups such as Everyone except external users or SharePoint groups. Nested security groups in the restricted access control groups list are supported for sharing.

For broader guidance on external sharing governance, see SharePoint External Sharing Governance in Microsoft 365.

Test Copilot and sharing to confirm restricted sites are ring‑fenced

Before you rely on restricted access control for sensitive sites, run a simple before‑and‑after test. The goal is that a user who currently has access loses direct access, cannot share the site outside the control groups, and no longer sees its content in Copilot.

  1. Have the test user open the chosen site and a clearly named document, then in a Copilot experience that uses organizational data ask for a summary of that document or search for its name. Because the user has permissions and Copilot grounds responses in organizational data they can access through Microsoft Graph, the document should appear in search or citations.Data, privacy, and security for Microsoft Copilot
  2. Enable site‑level access restriction at the tenant level, configure restricted access control on the site so that only the appropriate control groups are listed, remove the test user from all those control groups, and run Set-SPOTenant -AllowSharingOutsideRestrictedAccessControlGroups $false to restrict sharing outside control groups.
  3. Ask the test user to open the site URL and any previous sharing links to the test document; they should now see an access denial page. From another site they can access, have them try to share the protected site or its content with a colleague who is not in a control group; sharing should be blocked. After allowing time for search indexing to catch up, have the test user again search or ask Copilot about the test document; content from the protected site should no longer appear.

Known limitations and side effects

Restricted access control is powerful, but there are behaviors that can surprise admins if they are not aware of them.Restricted site access control

Permissions and group membership both matter

Adding people to restricted access control groups does not automatically give them access to the site or content. Users need both site or content permissions and membership in at least one restricted access control group, and removing them from all control groups can immediately block access even if their permissions remain.

Sharing behavior and search latency

By default, sharing sites and content does not follow the restricted site access policy, so users can send invitations to people who will be blocked when they try to open the content. To align sharing behavior, explicitly set Set-SPOTenant -AllowSharingOutsideRestrictedAccessControlGroups $false as described earlier.

Restricted access control policies are honored by organization‑wide search and Microsoft Copilot experiences, but Microsoft documents that it can take some time for these experiences to reflect new or updated policies. Index update latency depends on the number of items in a site, and larger sites can take longer for restricted access control to be fully honored in search and Copilot.

Restricted access control activity is logged as Microsoft Purview audit events for actions such as applying, removing, or changing site access restriction, and for site admin justifications when they update policies.Restricted site access control Microsoft also provides Start-SPORestrictedAccessForSitesInsights and Get-SPORestrictedAccessForSitesInsights commands to report on sites protected by restricted site access policy and access denials due to the policy.

To help users who see the access denial page understand what is happening, you can configure a Learn more link that points to your own guidance, such as a governance page on your intranet.

Set-SPOTenant -RestrictedAccessControlForSitesErrorHelpLink 'https://intranet.contoso.com/rac-help'

Get-SPOTenant | select RestrictedAccessControlForSitesErrorHelpLink

For a broader Copilot readiness view across permissions, oversharing, and site cleanup, see the SharePoint Copilot Readiness Checklist and Microsoft 365 Copilot Readiness service.

Preparing SharePoint for Microsoft 365 Copilot?

I help organizations review permissions, stale content, ownerless sites, and governance gaps before Copilot exposes content problems at scale.

16+ years experience Microsoft certified Government & enterprise

Free SharePoint planning resource

Before expanding Microsoft 365 usage, review your SharePoint risks.

Use the readiness checklist to review permissions, ownership, external sharing, retention, and lifecycle gaps before they become production issues.

Get the Checklist

Billy Peralta

SharePoint architect & Microsoft 365 consultant • 16+ years of experience

If you have questions about your SharePoint environment, feel free to reach out.

LinkedIn GitHub

Continue Reading

View all posts